What EDR does well
Endpoint detection and response monitors the computers it's installed on for malicious behavior, and it's good at it — catching known and many novel threats on managed endpoints, and giving responders the telemetry to investigate. Any serious security program should have it. The problem isn't EDR's quality; it's the boundaries of where it can operate and what it's designed to do.
Gap one: the devices EDR can't run on
A hospital runs tens of thousands of connected medical devices — infusion pumps, imaging systems, monitors — that cannot host an endpoint agent. EDR is structurally blind to them. Yet these are exactly the systems attackers use as entry points and hiding places, because everyone knows they're unprotected. An endpoint-only strategy has a hole shaped like the entire medical-device fleet.
Gap two: detection is not continuity
EDR's job is to detect and help respond. It is not designed to keep a hospital operating through an attack or to restore clinical systems afterward. When ransomware does land — and in a complex hospital, eventually something will — detection tells you it happened. It doesn't, on its own, contain the spread across the network in a patient-safe way or heal the systems that went down.
That's the difference between security and resilience. Security tries to stop the attack; resilience ensures that when an attack gets through, care keeps running and recovery is fast and clean.
Resilience is a layer, not a replacement
This isn't an argument to drop EDR — it's an argument to add what EDR can't provide. Immune complements endpoint tools with agentless protection for medical devices at the network boundary, care-aware containment that isolates threats without overriding clinical decisions, and self-healing recovery from immutable backups. EDR watches the endpoints it can; Immune covers the devices it can't and keeps the hospital running when something gets through.
Sources
- U.S. HHS 405(d) — Health Industry Cybersecurity Practices
- CISA — Healthcare and Public Health sector resources
Figures are drawn from the cited sources and were current as of publication. Content was rephrased for compliance with source licensing.
